astra-north

Network Security Solution Architect - Azure Virtual WAN (VWAN)

astra-north

Calgary, Alberta, CanadaContractPosted Jun 10, 2026

Job description

Job Title: Network Security Solution Architect | Azure VWAN, Firewall, DMZ, Cloud Security & Network Architecture Role: Network Security (Solution Architect) Duration: 12 Months Work Model: Hybrid (3 days/week in office) Key Responsibilities

  • Analyze current DMZ architecture, firewall rules, and security controls.
  • Assist in planning and executing the migration of servers and applications into a new or redesigned DMZ.
  • Identify and mitigate risks associated with exposing services to external networks.
  • Validate secure configurations during migration (network segmentation, access control, routing).
  • Design and enforce network segmentation strategies between DMZ, internal, and external zones.
  • Review and implement firewall policies (e.g., Palo Alto, Versa Networks).
  • Configure and validate NAT, ACLs, VPNs, and load balancers.
  • Ensure secure communication between tiers (web, app, database).
  • Assess existing firewall rules and eliminate redundant or risky rules.
  • Create least-privilege access rules for new DMZ architecture.
  • Perform rule recertification and documentation.
  • Maintain detailed documentation of:
  • Network diagrams (current and future state)
  • Firewall rule sets
  • Security controls implemented
  • Provide migration runbooks and rollback plans.
  • Lead end-to-end architecture design and governance for migration from Hub-and-Spoke to Azure VWAN, ensuring alignment with enterprise cloud and security standards.
  • Define and implement application-centric migration strategies, ensuring complete application stacks (DMZ and internal dependencies) are migrated together.
  • Design and oversee transit firewall decommissioning to reduce routing complexity, latency, and operational overhead.
  • Lead Web Application Firewall (WAF) compliance implementation in Azure for all internet-facing applications.
  • Define and execute roadmap to decommission legacy Hub-and-Spoke architecture and transition fully to VWAN.
  • Drive network architecture design, including:
  • Routing
  • UDR optimization
  • Traffic flows
  • Micro-segmentation within VWAN
  • Oversee firewall policy redesign and migration, ensuring secure connectivity between DMZ and internal environments.
  • Perform application dependency analysis across DMZ and internal systems to minimize latency and ensure seamless functionality.
  • Define migration patterns and playbooks, including:
  • Re-IP strategies
  • Domain migration
  • Service accounts
  • Cutover strategies
  • Provide hands-on architectural support during migration execution, including troubleshooting, validation, and real-time decision-making.
  • Collaborate with Cloud, Network, Security, Infrastructure, and Application teams for coordinated delivery.
  • Identify and mitigate risks related to:
  • Shared databases
  • Cross-network dependencies
  • Performance constraints
  • Establish and enforce architecture governance, standards, and reusable design patterns.
  • Support migration activities across EST and MST time zones, including critical migration windows.
  • Present architecture decisions and migration impacts to senior stakeholders, translating technical concepts into business insights.